GoogleKmsCryptoKey class final

Factory wrapper for google_kms_crypto_key.

A CryptoKey represents a logical key that can be used for cryptographic operations.

~> Note: CryptoKeys cannot be deleted from Google Cloud Platform. Destroying a Terraform-managed CryptoKey will remove it from state and delete all CryptoKeyVersions, rendering the key unusable, but will not delete the resource from the project. When Terraform destroys these keys, any data previously encrypted with these keys will be irrecoverable. For this reason, it is strongly recommended that you add lifecycle hooks to the resource to prevent accidental destruction.

Example:

final ring = GoogleKmsKeyRing(
  'main',
  name: TfArg.literal('main-ring'),
  location: TfArg.literal('asia-northeast1'),
);

final cryptoKey = GoogleKmsCryptoKey(
  'payments',
  name: TfArg.literal('payments'),
  keyRing: ring.ref,
  purpose: KmsKeyPurpose.encryptDecrypt,
  // Must be > 86400s (1 day). `TfArg.duration` converts the
  // Duration into the `"{seconds}s"` form Terraform expects.
  rotationPeriod: TfArg.duration(const Duration(days: 90)),
  versionTemplate: KmsCryptoKeyVersionTemplate(
    algorithm: .literal('GOOGLE_SYMMETRIC_ENCRYPTION'),
    protectionLevel: KmsProtectionLevel.software,
  ),
);

Note: CryptoKeys cannot be deleted from GCP. Destroying a Terraform-managed CryptoKey removes it from state and renders all CryptoKeyVersions unusable but does not delete the resource from the project. Consider attaching lifecycle { prevent_destroy = true } for production keys.

Inheritance

Constructors

GoogleKmsCryptoKey(String localName, {required TfArg<String> name, required RefTo<GoogleKmsKeyRing> keyRing, KmsKeyPurpose? purpose, TfArg<String>? rotationPeriod, TfArg<Map<String, String>>? labels, TfArg<bool>? skipInitialVersionCreation, TfArg<String>? destroyScheduledDuration, TfArg<bool>? importOnly, TfArg<String>? cryptoKeyBackend, KmsCryptoKeyVersionTemplate? versionTemplate, LifecycleOptions? lifecycle, List<TfAddressed>? dependsOn, StackProvider? provider, TfTimeouts? timeouts})

Properties

argMap → Map<String, TfArg?>
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name). Synth emits these keys directly; the factory is responsible for the camelCase → snake_case translation at construction time.
finalinherited
cryptoKeyBackend → TfRef<String>
Reference to crypto_key_backend attribute.
no setter
defaultProvider → String
The provider name a block without provider uses: by default the prefix of terraformType (google for google_pubsub_topic).
no setterinherited
deletionPolicy → TfRef<String>
Reference to deletion_policy attribute.
no setter
dependsOn → List<TfAddressed>?
Optional depends_on = [...]: the resources, data sources and module calls this block waits for, e.g. dependsOn: [api, ...apiDeps]. Terraform takes whole blocks only, so an entry is never an attribute.
finalinherited
destroyScheduledDuration → TfRef<String>
Reference to destroy_scheduled_duration attribute.
no setter
effectiveLabels → TfRef<Map<String, String>>
Reference to effective_labels attribute.
no setter
hashCode → int
The hash code for this object.
no setterinherited
id → TfRef<String>
Reference to id attribute.
no setter
importOnly → TfRef<bool>
Reference to import_only attribute.
no setter
keyRing → TfRef<String>
Reference to key_ring attribute.
no setter
kind → ResourceKind
Always ResourceKind.resource. Overridden by Data.
no setterinherited
labels → TfRef<Map<String, String>>
Reference to labels attribute.
no setter
lifecycle → LifecycleOptions?
Optional lifecycle { ... } block.
finalinherited
localName → String
User-supplied local name within a Stack.
finalinherited
name → TfRef<String>
Reference to name attribute.
no setter
primary → TfRef<List<Map<String, Object?>>>
Reference to primary attribute.
no setter
provider → StackProvider?
Optional Terraform provider meta-argument: the provider configuration this block uses, e.g. the aliased GoogleProvider(alias: 'eu') the Stack registered with addProvider.
finalinherited
purpose → TfRef<String>
Reference to purpose attribute.
no setter
ref → RefTo<GoogleKmsCryptoKey>
A reference to this resource, for arguments typed RefTo<GoogleKmsCryptoKey>.
no setter
rotationPeriod → TfRef<String>
Reference to rotation_period attribute.
no setter
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
sensitiveFields → Set<String>
Field names that are @Sensitive per the IR-derived per-resource constant. Curated factories override with a baked-in static const Set<String> (file-private in v0.5+).
no setteroverride
skipInitialVersionCreation → TfRef<bool>
Reference to skip_initial_version_creation attribute.
no setter
supportsDeletionProtection → bool
Capability flag: true when this resource's underlying Terraform schema has a deletion_protection boolean attribute that the synth-time devMode flow can flip to false. Defaults to false; the codegen emitter overrides this to true for wrappers whose schema includes the attribute.
no setterinherited
terraformLabels → TfRef<Map<String, String>>
Reference to terraform_labels attribute.
no setter
terraformType → String
Terraform resource type, e.g. google_pubsub_topic.
finalinherited
tfAddress → String
Terraform address <terraformType>.<localName>, e.g. google_pubsub_topic.orders.
no setterinherited
timeouts → TfTimeouts?
Optional timeouts { ... } block: how long Terraform waits for each operation. Provider-neutral like lifecycle — synth copies the duration strings verbatim, and terraform validate decides whether this resource's schema declares the operations set here.
finalinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Constants

tfType → const String